Impact
This vulnerability allows an application to read a user’s Safari bookmarks without performing the required entitlement verification. The missing entitlement check gives the app unauthorized access to potentially sensitive bookmark information, compromising user confidentiality. The flaw represents a Missing Authorization weakness, as defined by CWE‑862.
Affected Systems
Apple iPadOS and Apple macOS are affected. On iPadOS, the vulnerability exists in all releases prior to iPadOS 17.7.7. On macOS, the flaw is present on Sequoia, Sonoma, and Ventura versions older than macOS Sequoia 15.4, macOS Sonoma 14.7.5, and macOS Ventura 13.7.5 respectively.
Risk and Exploitability
With a CVSS score of 9.8, the vulnerability is rated critical. The EPSS score is less than 1 %, indicating that, as of the current data, the likelihood of exploitation is low. The flaw resides in a local attack vector whereby a malicious application on the device can access Safari bookmarks. Though not listed in the CISA KEV catalog, its high severity warrants prompt patching.
OpenCVE Enrichment
EUVD